VA-003 Compare and configure secrets engines Practice Question
Which TWO best practices should be followed when tuning secrets engine mounts?
⚠ Common exam trap
VA-003 often tests the confusion between per-mount lease tuning parameters (default_lease_ttl, max_lease_ttl) and server-wide audit/policy settings, tempting candidates to pick audit logging or policy changes as 'tuning' best practices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure 'max_lease_ttl' to limit the maximum duration secrets can be valid
Option B is correct because configuring 'max_lease_ttl' on a secrets engine mount caps the absolute lifetime of any secret issued by that mount, preventing clients from renewing or holding credentials indefinitely and thereby limiting exposure if a secret leaks. Option C is correct because setting 'default_lease_ttl' to a low value appropriate for the engine ensures that, absent an explicit request, issued secrets expire quickly, which is a core Vault best practice for reducing the blast radius of compromised credentials. Option A is not a mount-tuning best practice in this context; audit logging is enabled at the audit device level and records requests globally rather than being a per-mount tuning parameter. Option D is incorrect because a high default lease TTL increases the window in which a leaked secret remains valid, contradicting the goal of tight lease lifetimes. Option E is incorrect because the 'default' policy is a global Vault policy attached to tokens, not something that is disabled per secrets engine mount.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable audit logging on the mount to track secret access
Why it's wrong here
Audit logging is configured at the Vault server or device level, not per secrets engine mount, so enabling it on a mount is not a mount-tuning practise. It would be correct as a general Vault operational control for tracking all secret access across the cluster.
- ✓
Configure 'max_lease_ttl' to limit the maximum duration secrets can be valid
Why this is correct
Setting max_lease_ttl caps how long any credential issued by the mount can remain valid, forcing periodic renewal or reissuance. This satisfies the tuning requirement by bounding exposure if a secret leaks, rather than letting leases persist indefinitely.
- ✓
Set 'default_lease_ttl' to a low value appropriate for the secrets engine
Why this is correct
A low default_lease_ttl shortens the lifetime of issued credentials unless clients explicitly request longer, reducing the window in which leaked secrets remain usable. This satisfies the tuning requirement by aligning default validity with the engine's sensitivity.
- ✗
Set a high default lease TTL to reduce renewals
Why it's wrong here
A high default lease TTL increases the window in which a leaked or compromised credential remains valid, weakening revocation. Long TTLs suit static, long-lived workloads where renewal overhead is genuinely costly, but tuning mounts should favour shorter TTLs with renewal.
- ✗
Disable the 'default' policy for the mount to restrict access
Why it's wrong here
The 'default' policy is a Vault-wide policy attached to tokens, not a per-mount setting, so it cannot be disabled for an individual secrets engine mount. Restricting mount access is done through mount-specific policies and token capabilities instead.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 366 original VA-003 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official HashiCorp exam blueprint
This VA-003 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the VA-003 exam.